The Most Expensive Lesson of My Life: Details of SIM Port Hack
medium.com
medium.com
If I get unexpectedly logged out of my email account, even if I can log right back in, this should already be at "something seriously fishy is going on and I need to investigate immediately", such as checking the account for any activity. Not being able to log in to my email is "check my provider's status page to make sure they're not having a widespread outage, and if they're not, get on the horn with support immediately".
As the author says, your email account is the keys to the kingdom for virtually every other account you have. Anything that threatens it is serious business.
I thought the author did a good job describing how he rationalized away these warning signals as flakiness, and had a bad mental model of the situation ("SIM card is being weird") that prevented him taking timely action. He also mentioned outside factors (needing to sleep, stress at work) that affected his judgement.
It's easy to say this would never happen to you, but even sophisticated people get caught by this stuff, since we are in the end human. Writing this article in the aftermath of losing so much money was a brave and considerate gesture.
> Many of you are thinking, "Jesus, I would never fall for the "the check's in the mail, we had trouble with the wire transfer, the money is coming in from our affiliate in New York, I'll get you the tracking number" routine day after day. But sociopaths are very, very good at this. You don't want to believe you've been conned, you don't want to believe you have to go hire a lawyer and file a lawsuit, you don't want to believe someone can do this to you, you want the income that this transaction promises, and often you don't want to go tell your superiors — so you keep hoping that the money is coming any day now. It can happen to you. It's happened to very smart lawyers I know. It's happened to me. And I used to put these people in jail. So don't judge the victims too harshly. When you find yourself in such a situation, you've got to focus — to convince yourself to bail out and cancel the contract, stop providing services, and file suit if necessary.
2FA and all are secure enough, the problem for him was that his mobile phone number was the only thing needed to gain access because the attacker wad (1) able to reset the password for the mail account by sms and (2) 2fawas sms based.
There should be _absolutely no_ way of resetting the password of your mail account besides some pregenerated tokens you are keeping safe somewhere.
The second is "recovery phone number" in a different settings pane. That one is easy to miss!
Here's a direct link, takes one minute to audit yours: https://myaccount.google.com/u/0/security?hl=en
With flow charts and timelines.
Assuming it was a Google account with 2 factor enabled, you aren't allowed to reset the password with an SMS only.
You need two factors. I suspect his original password was leaked, or perhaps he had a recovery email address also broken into?